rexml
An XML toolkit for Ruby
Activity
- Latest release
- 1y ago
- Total releases
- 29
- Cadence
- ~22 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- BSD-2-Clause
- First release
- Dec 04, 2018
| Version | Released | |
|---|---|---|
3.4.4
patch
| ||
3.4.3
patch
| ||
3.4.2
patch
| ||
3.4.1
patch
1 CVE
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0
minor
1 CVE
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.9
patch
1 CVE
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.8
patch
2 CVEs
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.7
patch
2 CVEs
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.6
patch
2 CVEs
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.5
patch
3 CVEs
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.3
patch
3 CVEs
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.4
patch
3 CVEs
CVE-2025-58767
GHSA-c2f4-jgmc-q2r5
Sep 17, 2025
REXML has DoS condition when parsing malformed XML file
Low
Local
Low
None
None
ImpactThe REXML gems from 3.3.3 to 3.4.1 have a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesREXML gems 3.4.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
Fixed in
3.4.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.2
patch
4 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.1
patch
5 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0
minor
5 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.9
patch
5 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.8
patch
5 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.7
patch
5 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.6
patch
6 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.1.9.1
patch
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev | ||
3.2.5
patch
6 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.4
patch
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev | ||
3.2.3
patch
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev | ||
3.2.2
patch
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev | ||
3.2.1
patch
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev | ||
3.2.0
minor
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev | ||
3.1.9
patch
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev | ||
3.1.8
patch
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev | ||
3.1.7.3
initial
7 CVEs
CVE-2024-49761
GHSA-2rxp-v6pw-ch6m
CVE-2025-10990
Oct 28, 2024
REXML ReDoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. Note that Ruby 3.1 will reach EOL on 2025-03. PatchesThe REXML gem 3.3.9 or later include the patch to fix the vulnerability. WorkaroundsUse Ruby 3.2 or later instead of Ruby 3.1. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 11 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
Fixed in
3.3.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-43398
GHSA-vmwr-mc7x-5vc3
Aug 22, 2024
REXML denial of service vulnerability
High
Network
Low
None
None
ImpactThe REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like PatchesThe REXML gem 3.3.6 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with tree parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 8 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
Fixed in
3.3.6
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41946
GHSA-5866-49gr-22v4
Aug 02, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. If you need to parse untrusted XMLs with SAX2 or pull parser API, you may be impacted to this vulnerability. PatchesThe REXML gem 3.3.3 or later include the patch to fix the vulnerability. WorkaroundsDon't parse untrusted XMLs with SAX2 or pull parser API. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-41123
GHSA-r55c-59qm-vjw6
Aug 01, 2024
REXML DoS vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.3 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 5 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
Fixed in
3.3.3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-39908
GHSA-4xqq-m2hx-25v8
Jul 16, 2024
REXML denial of service vulnerability
Medium
Network
Low
None
None
ImpactThe REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. PatchesThe REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
+ 4 more Show less
3.2.8
3.2.9
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-35176
GHSA-vg3r-rm7w-2xgh
May 16, 2024
REXML contains a denial of service vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactThe REXML gem before 3.2.6 has a DoS vulnerability when it parses an XML that has many If you need to parse untrusted XMLs, you may be impacted to this vulnerability. PatchesThe REXML gem 3.2.7 or later include the patch to fix this vulnerability. WorkaroundsDon't parse untrusted XMLs. References
Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
Fixed in
3.2.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-28965
GHSA-8cr8-4vfw-mr7h
BIT-ruby-2021-28965
BIT-ruby-min-2021-28965
Apr 30, 2021
REXML round-trip instability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing. Affected versions
3.1.7.3
3.1.8
3.1.9
3.1.9.1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
Fixed in
3.2.5
References
Updated Jan 27, 2025 · Source: OSV.dev |